NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / Security flaw allows stolen credit card use on digital wallets
    Summarize
    Next Article
    Security flaw allows stolen credit card use on digital wallets
    Attackers can bypass multi-factor authentication with ease

    Security flaw allows stolen credit card use on digital wallets

    By Mudit Dube
    Aug 20, 2024
    06:52 pm

    What's the story

    A recent study has revealed that popular digital wallets like Apple Pay, Google Pay, and PayPal could potentially be used to conduct transactions with stolen credit cards.

    The research was conducted by a team of cybersecurity experts including Raja Hasnain Anwar and Muhammad Taqi Raza from the University of Massachusetts Amherst, and Syed Rafiul Hussain from Penn State.

    Their findings were presented in a paper titled "In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free Shopping."

    Security flaws

    Researchers expose vulnerabilities in digital wallet security

    The researchers uncovered critical vulnerabilities in the security protocols of major digital wallet apps and US banks.

    They demonstrated how attackers could exploit weaknesses in authentication, authorization, and access control mechanisms to add stolen credit cards to their own digital wallets and make unauthorized purchases.

    The study's lead author, Anwar, outlined a potential attack scenario where a thief, armed with a stolen credit card, could use publicly accessible databases to locate the victim's address, facilitating fraudulent transactions.

    Authentication loophole

    Attackers can bypass multi-factor authentication

    The researchers highlighted that an attacker could bypass multi-factor authentication (MFA) by opting for a knowledge-based authentication (KBA) scheme.

    This involves using the 'call-based' option to add the card to their wallet, where they provide KBA-related information like date of birth or last four digits of social security number.

    Some KBA schemes only require one data point such as billing ZIP code, billing street address, date of birth, or last four digits of social security number.

    Token issue

    Token authorization allows continued access to stolen cards

    The researchers found that canceling a stolen card does not prevent its use in digital wallets.

    When a card is authenticated, the bank issues a token authorizing purchases which is stored in the digital wallet.

    This token remains active even if the original card is canceled and replaced, allowing attackers to continue using it for transactions.

    The study also revealed that banks do not require point-of-sale terminals in stores to verify the identity of the cardholder, further compounding this issue.

    Transaction abuse

    Recurring transactions and locked cards: A potential for abuse

    The study also found that recurring transactions, such as monthly charges, are processed in a way that can be exploited.

    An attacker can trick a merchant into tagging a transaction as "recurring," which will be processed even if the relevant payment card has been locked.

    This is because banks allow recurring payments on locked cards to honor contracts between users and merchants, ensuring continuity of subscription services and avoiding negative credit events due to missed payments.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Apple Pay
    PayPal
    Cybercrimes

    Latest

    Who is India's most successful Test captain on England soil? Indian Cricket Team
    No duty cuts on British wine in India-UK trade deal United Kingdom
    Sneh Rana records career-best WODI returns against SL; Amanjot shines Indian Women's Cricket Team
    TVS's cheapest e-scooter to be launched soon: What we know TVS Motor Company

    Apple Pay

    iPhone sales drop just before 10th anniversary Apple
    Alipay wages war against Apple Pay for US market United States of America
    Apple unveils Business Chat, brings customer service /shopping into iMessage Facebook
    Here's how to sign up for Jio's 'free' phone Reliance Jio

    PayPal

    Nigeria: A major hub for African e-commerce start ups Nigeria
    Berkeley's Premier Cru wine seller pleads guilty to fraud Federal Bureau of Investigation
    Paypal founder Peter Thiel considering running for California governor Donald Trump
    Gmail rolls out new feature to send and request money Google

    Cybercrimes

    AI-powered job scams on the rise: How to protect yourself Google
    AT&T data breach: Phone records of 'nearly all' customers stolen Cybersecurity
    How to tackle spam calls on your Android smartphone Android
    Worried about cybercrimes? Follow these tips to stay safe Cybersecurity
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025